网络词典 - 网络安全术语表 API

API ID 14093

359 网络安全术语:攻击 CVE 工具 协议 概念 简短和完整定义 示例 相关术语 技能水平 JSON

API 文档

端点

请求
总术语计数加上每个类别和每个技能水平的计数 返回网络安全术语表的 JSON 统计数据
Endpoint ID: 34798
GET https://zylalabs.com/api/14093/cyberdict+-+cybersecurity+glossary+api/34798/getstats
输入参数

剩余免费测试请求:3 / 3。

此端点不需要任何输入参数。

API 示例响应
JSON
{
    "total": 359,
    "categories": [
        {
            "category": "Attack",
            "count": 74
        },
        {
            "category": "Concept",
            "count": 53
        },
        {
            "category": "Protocol",
            "count": 45
        },
        {
            "category": "Tool",
            "count": 41
        },
        {
            "category": "Methodology",
            "count": 40
        },
        {
            "category": "Defense",
            "count": 23
        },
        {
            "category": "Certification",
            "count": 19
        },
        {
            "category": "Vulnerability",
            "count": 17
        },
        {
            "category": "Networking",
            "count": 16
        },
        {
            "category": "Role",
            "count": 10
        },
        {
            "category": "Slang",
            "count": 6
        },
        {
            "category": "Principles",
            "count": 5
        },
        {
            "category": "ICS",
            "count": 4
        },
        {
            "category": "AI/ML Security",
            "count": 3
        },
        {
            "category": "Hardware",
            "count": 3
        }
    ],
    "skillLevels": [
        {
            "skill_level": "Intermediate",
            "count": 183
        },
        {
            "skill_level": "Advanced",
            "count": 122
        },
        {
            "skill_level": "Beginner",
            "count": 54
        }
    ]
}
获取统计数据 — 代码片段

curl --location --request GET 'https://zylalabs.com/api/14093/cyberdict+-+cybersecurity+glossary+api/34798/getstats' --header 'Authorization: Bearer YOUR_API_KEY' 


    
请求
按字母顺序返回网络安全术语 所有查询参数都是可选的 并且与 AND 结合 通过 q 搜索 通过类别或技能水平过滤 通过 id 获取术语 并使用 limit 和 offset 进行分页
Endpoint ID: 34799
GET https://zylalabs.com/api/14093/cyberdict+-+cybersecurity+glossary+api/34799/listterms
输入参数

错误 — 端点功能

对象 描述
q 可选 Optional text search across cybersecurity terms.
category 可选 Optional category filter: Attack, Concept, Protocol, Tool, Methodology and other available categories.
skill_level 可选 Optional skill level: beginner, intermediate or advanced.
id 可选 Optional numeric term ID to retrieve a single term.
limit 可选 Optional number of terms returned per page.
offset 可选 Optional number of matching terms to skip for pagination.

剩余免费测试请求:3 / 3。


输入参数

q
category
skill_level
id
limit
offset
API 示例响应
JSON
{
    "terms": [
        {
            "id": 362,
            "term": "1337 (Leet)",
            "short_description": "Alternative alphabet using symbols and numbers to replace letters, popular in hacker culture.",
            "full_description": "1337 (pronounced \"leet\"), derived from \"elite\" is a type of internet slang where standard letters are replaced with various combinations of ASCII characters, numbers, and symbols. It originated in 1980s bulletin board systems and early hacker culture as a way to obfuscate text and demonstrate technical prowess. The simplest form replaces letters with similar-looking numbers (E=3, A=4, T=7, etc.), while more complex versions use creative substitutions. While less common in professional contexts today, elements of leet speak remain in technical culture, gaming communities, and as a way to bypass simple text filters.",
            "category": "Slang",
            "related_terms": "[\"Hacker Culture\",\"ASCII Art\",\"Obfuscation\",\"Internet Slang\",\"Text Substitution\"]",
            "examples": "[\"Converting \\\"Hacker\\\" to \\\"H4ck3r\\\" or more extremely to \\\"|\\\\|4(|<3|2\\\"\",\"Using \\\"pwn\\\" (derived from \\\"own\\\" as \\\"p\\\" resembles \\\"o\\\" in some fonts) to indicate domination or compromise\",\"Creating passwords with leet substitutions (though predictable substitutions are vulnerable to rule-based cracking)\",\"Online handles and group names incorporating leet speak like \\\"Th3 R34l D34l\\\"\"]",
            "skill_level": "Beginner"
        },
        {
            "id": 361,
            "term": "2FA (Two-Factor Authentication)",
            "short_description": "Two-Factor Authentication - adds an extra verification layer beyond passwords",
            "full_description": "Two-Factor Authentication (2FA) is a security method that requires users to provide two different authentication factors to verify themselves. This provides a higher level of security than single-factor authentication (like a password alone) because even if one factor is compromised, the second factor would still prevent unauthorized access. The factors typically come from different categories: something you know (password), something you have (security token or mobile device), or something you are (biometrics). Common implementations include sending a code via SMS, using an authenticator app to generate time-based one-time passwords (TOTP), or using hardware security keys.",
            "category": "Defense",
            "related_terms": "[\"MFA\",\"OTP\",\"TOTP\",\"Authentication\",\"Hardware Token\"]",
            "examples": "[\"Using Google Authenticator to generate a verification code after entering a password\",\"Receiving a one-time code via SMS when logging into a banking website\",\"Plugging in a YubiKey hardware token to complete the login process\"]",
            "skill_level": "Beginner"
        },
        {
            "id": 360,
            "term": "Actions on Objectives",
            "short_description": "The final phase where attackers accomplish their goals in the target environment.",
            "full_description": "Actions on Objectives is the final phase of the Cyber Kill Chain, where attackers accomplish their ultimate goals after establishing presence in the target environment. These objectives vary based on the attacker's motivations and might include data exfiltration, system or data destruction, ransomware deployment, espionage, or using the compromised system as a launching point for further attacks. This phase represents the culmination of the attack and often causes the most direct harm to the victim organization.",
            "category": "Methodology",
            "related_terms": "[\"Cyber Kill Chain\",\"Data Exfiltration\",\"Ransomware\",\"Espionage\",\"Destruction\"]",
            "examples": "[\"Exfiltrating sensitive intellectual property to an attacker-controlled server\",\"Deploying ransomware across the network to encrypt critical business data\",\"Establishing persistence within critical infrastructure to enable future sabotage\"]",
            "skill_level": "Intermediate"
        },
        {
            "id": 359,
            "term": "AdminSDHolder",
            "short_description": "Active Directory protection mechanism that can be abused for persistence",
            "full_description": "AdminSDHolder is a special object in Active Directory designed to protect privileged accounts from unauthorized modifications by enforcing a specific security descriptor. Every 60 minutes, a background process (SDProp) copies the AdminSDHolder's access control list to all protected accounts and groups. While this is a security feature, attackers can abuse it for persistence by modifying the AdminSDHolder object itself to grant themselves persistent access to all privileged accounts. Since these changes are continuously reapplied by the system, traditional remediation approaches may fail to remove the attacker's access.",
            "category": "Vulnerability",
            "related_terms": "[\"Active Directory\",\"Access Control List\",\"SDProp\",\"Protected Groups\",\"Persistence\",\"Security Descriptor\"]",
            "examples": "[\"Adding a backdoor user to AdminSDHolder's ACL for persistent admin access\",\"Maintaining persistence that survives regular cleanup attempts\",\"Hiding access rights that propagate to all protected accounts\"]",
            "skill_level": "Advanced"
        },
        {
            "id": 358,
            "term": "AdminSDHolder Abuse",
            "short_description": "Exploiting the protected group mechanism in Active Directory to maintain persistent privileged access.",
            "full_description": "AdminSDHolder abuse is a sophisticated persistence technique in Active Directory environments that exploits the AdminSDHolder object and Security Descriptor propagation mechanism. The AdminSDHolder object in Active Directory contains a security descriptor that is applied to protected groups (like Domain Admins) every 60 minutes by the SDProp process. By modifying the ACLs on the AdminSDHolder object, attackers can grant themselves persistent rights to all protected accounts and groups, even if direct permissions on those objects are later removed. This technique is particularly stealthy because it leverages a legitimate AD protection mechanism and the changes persist through regular security measures like password resets.",
            "category": "Attack",
            "related_terms": "[\"Active Directory\",\"Persistence\",\"ACL\",\"Protected Groups\",\"SDProp\"]",
            "examples": "[\"Adding a 'Full Control' ACE for a backdoor account to the AdminSDHolder object\",\"Granting 'GenericAll' rights to maintain the ability to reset passwords of privileged accounts\",\"Using DCSync rights on AdminSDHolder to maintain the ability to extract password hashes\"]",
            "skill_level": "Advanced"
        },
        {
            "id": 357,
            "term": "Admission Controller",
            "short_description": "Kubernetes components intercepting requests to validate and mutate resources",
            "full_description": "Admission Controllers in Kubernetes are plugins that intercept API requests to create, modify, or delete resources before they are persisted. These controllers serve two primary functions: validating requests against custom security policies, and mutating requests to enforce security controls or inject configuration. Security-focused admission controllers can enforce pod security standards, prevent privileged containers, implement network policies, and validate image sources. Tools like OPA Gatekeeper and Kyverno provide customizable policy enforcement through admission control.",
            "category": "Defense",
            "related_terms": "[\"Kubernetes\",\"Container Security\",\"Policy Enforcement\",\"Security Controls\",\"OPA\",\"Webhook\"]",
            "examples": "[\"PodSecurityPolicy enforcing container security standards\",\"OPA Gatekeeper validating resource configurations against policies\",\"MutatingAdmissionWebhook injecting security sidecars automatically\"]",
            "skill_level": "Advanced"
        },
        {
            "id": 356,
            "term": "Adversarial Example (AI/ML)",
            "short_description": "Inputs to machine learning models intentionally designed to cause the model to make a mistake.",
            "full_description": "An adversarial example in machine learning is an input that has been slightly modified in a way that is imperceptible to humans but causes a machine learning model (e.g., an image classifier, a spam filter) to misclassify it with high confidence. These attacks highlight vulnerabilities in ML models. Creating effective adversarial examples often requires knowledge of the model's architecture or access to query the model. Defending against them is an active area of research.",
            "category": "AI/ML Security",
            "related_terms": "[\"Machine Learning Security\",\"Data Poisoning\",\"Model Evasion\",\"AI Security\"]",
            "examples": "[\"Adding a small, almost invisible noise pattern to an image of a panda, causing an image recognition model to classify it as a gibbon.\",\"Slightly altering a spam email to bypass a machine learning-based spam filter.\",\"Crafting audio commands that are unintelligible to humans but recognized by voice assistants.\"]",
            "skill_level": "Advanced"
        },
        {
            "id": 355,
            "term": "AES (Advanced Encryption Standard)",
            "short_description": "A symmetric block cipher widely adopted by the U.S. government and used worldwide."
        }
    ],
    "_note": "Response truncated for documentation purposes"
}
错误 — 代码片段

curl --location --request GET 'https://zylalabs.com/api/14093/cyberdict+-+cybersecurity+glossary+api/34799/listterms' --header 'Authorization: Bearer YOUR_API_KEY' 


    

API 访问密钥和身份验证

注册后,每个开发者都会被分配一个个人 API 访问密钥,这是一个唯一的字母和数字组合,用于访问我们的 API 端点。要使用 网络词典 - 网络安全术语表 API 进行身份验证,只需在 Authorization 标头中包含您的 bearer token。

标头
标头 描述
授权 必需 应为 Bearer access_key. 订阅后,请查看上方的"您的 API 访问密钥"。

无长期承诺。随时升级、降级或取消。 免费试用包括最多 50 个请求。

(年度计费可节省 2 个月 🎉)

起价
$10,000/年


  • 自定义数量
  • 自定义速率限制
  • 专业客户支持
  • 实时 API 监控

概览

359个网络安全术语:攻击 CVE 工具 协议 概念 简短和完整的定义 示例 相关术语 技能等级 JSON

网络词典 - 网络安全术语表 API FAQs

CyberDict 提供 359 个网络安全术语,包括名称、简短定义和完整定义、示例、相关术语、类别和技能水平。术语端点支持文本搜索、类别和技能水平过滤器、数字 ID 和分页。统计端点返回总数和计数。将其用于培训、测验、工具提示、聊天机器人和 SOC 入职。内容按原样提供用于教育和防御安全。未提供任何担保。对安全关键的信息进行核实,使用主要来源。不要将原始数据集作为竞争词汇表进行转售

使用listTerms端点 可选的q参数用于搜索术语 category和skill_level参数可以缩小结果 所有过滤器以AND组合 使用id来检索单个术语

使用限制控制返回的匹配项数量,使用偏移量跳过匹配项。两个参数都是可选的。术语按字母顺序排列

每个术语包含术语名称 简短定义 完整描述 示例 相关术语 类别和技能水平 技能水平分为初级 中级和高级 相关术语支持链接的词汇表和知识图谱

GetStats端点返回按类别和技能等级分类的总术语数量和计数 当前数据集包含359个术语 响应为JSON并由Cloudflare边缘提供

一般常见问题

Zyla API Hub 就像一个大型 API 商店,您可以在一个地方找到数千个 API。我们还为所有 API 提供专门支持和实时监控。注册后,您可以选择要使用的 API。请记住,每个 API 都需要自己的订阅。但如果您订阅多个 API,您将为所有这些 API 使用相同的密钥,使事情变得更简单。
价格以 USD(美元)、EUR(欧元)、CAD(加元)、AUD(澳元)和 GBP(英镑)列出。我们接受所有主要的借记卡和信用卡。我们的支付系统使用最新的安全技术,由 Stripe 提供支持,Stripe 是世界上最可靠的支付公司之一。如果您在使用卡片付款时遇到任何问题,请通过 [email protected]

此外,如果您已经以这些货币中的任何一种(USD、EUR、CAD、AUD、GBP)拥有有效订阅,该货币将保留用于后续订阅。只要您没有任何有效订阅,您可以随时更改货币。
定价页面上显示的本地货币基于您 IP 地址的国家/地区,仅供参考。实际价格以 USD(美元)为单位。当您付款时,即使您在我们的网站上看到以本地货币显示的等值金额,您的卡片对账单上也会以美元显示费用。这意味着您不能直接使用本地货币付款。
有时,银行可能会因其欺诈保护设置而拒绝收费。我们建议您首先联系您的银行,检查他们是否阻止了我们的收费。此外,您可以访问账单门户并更改关联的卡片以进行付款。如果这些方法不起作用并且您需要进一步帮助,请通过 [email protected]
价格由月度或年度订阅决定,具体取决于所选计划。
API 调用根据成功请求从您的计划中扣除。每个计划都包含您每月可以进行的特定数量的调用。只有成功的调用(由状态 200 响应指示)才会计入您的总数。这确保失败或不完整的请求不会影响您的月度配额。
Zyla API Hub 采用月度订阅系统。您的计费周期将从您购买付费计划的那一天开始,并在下个月的同一日期续订。因此,如果您想避免未来的费用,请提前取消订阅。
要升级您当前的订阅计划,只需转到 API 的定价页面并选择您要升级到的计划。升级将立即生效,让您立即享受新计划的功能。请注意,您之前计划中的任何剩余调用都不会转移到新计划,因此在升级时请注意这一点。您将被收取新计划的全部金额。
要检查您本月剩余多少 API 调用,请参考响应标头中的 "X-Zyla-API-Calls-Monthly-Remaining" 字段。例如,如果您的计划允许每月 1,000 个请求,而您已使用 100 个,则响应标头中的此字段将显示 900 个剩余调用。
要查看您的计划允许的最大 API 请求数,请检查 "X-Zyla-RateLimit-Limit" 响应标头。例如,如果您的计划包括每月 1,000 个请求,此标头将显示 1,000。
"X-Zyla-RateLimit-Reset" 标头显示您的速率限制重置之前的秒数。这告诉您何时您的请求计数将重新开始。例如,如果它显示 3,600,则意味着还有 3,600 秒直到限制重置。
是的,您可以随时通过访问您的账户并在账单页面上选择取消选项来取消您的计划。请注意,升级、降级和取消会立即生效。此外,取消后,您将不再有权访问该服务,即使您的配额中还有剩余调用。
为了让您有机会在没有任何承诺的情况下体验我们的 API,我们提供 7 天免费试用,允许您免费进行最多 50 次 API 调用。此试用只能使用一次,因此我们建议将其应用于您最感兴趣的 API。虽然我们的大多数 API 都提供免费试用,但有些可能不提供。试用在 7 天后或您进行了 50 次请求后结束,以先发生者为准。如果您在试用期间达到 50 次请求限制,您需要"开始您的付费计划"以继续发出请求。您可以在个人资料中的订阅 -> 选择您订阅的 API -> 定价标签下找到"开始您的付费计划"按钮。或者,如果您在第 7 天之前不取消订阅,您的免费试用将结束,您的计划将自动计费,授予您访问计划中指定的所有 API 调用的权限。请记住这一点以避免不必要的费用。
7 天后,您将被收取试用期间订阅的计划的全额费用。因此,在试用期结束前取消很重要。因忘记及时取消而提出的退款请求不被接受。
当您订阅 API 免费试用时,您可以进行最多 50 次 API 调用。如果您希望超出此限制进行额外的 API 调用,API 将提示您执行"开始您的付费计划"。您可以在个人资料中的订阅 -> 选择您订阅的 API -> 定价标签下找到"开始您的付费计划"按钮。
付款订单在每月 20 日至 30 日之间处理。如果您在 20 日之前提交请求,您的付款将在此时间范围内处理。
您可以通过我们的聊天渠道联系我们以获得即时帮助。我们始终在线,时间为上午 8 点至下午 5 点(EST)。如果您在该时间之后联系我们,我们将尽快回复您。此外,您可以通过 [email protected]

相关 API


您可能还喜欢